Skip to Content
DocumentationGetting StartedDeployment Sovereignty

Deployment Sovereignty

The Vault is designed to give organisations full control over where and how their custody infrastructure runs. Choose from three deployment models depending on your data residency requirements, operational capacity, and regulatory obligations.

Deployment Models at a Glance

SaaSHybridOn-Premises
InfrastructureManaged by The VaultSharedFully customer-managed
Key share custodyServer shares in The Vault cloudServer shares split across both environmentsAll shares on customer infrastructure
Data residencyThe Vault cloud regionSplit — sensitive data on-premFully within customer perimeter
Operational burdenMinimalModerateFull
Time to go liveDays1–2 weeks2–4 weeks
Best forStartups, fintechsRegulated entities wanting managed services + key controlBanks, institutions with strict data residency

SaaS (Cloud-Hosted)

The fully managed option. All platform services, server signers, and data are hosted in The Vault’s cloud infrastructure.

You manage:

  • API integration from your application
  • Mobile signer devices (your team holds them)
  • Transaction policies and approval workflows

We manage:

  • Infrastructure, uptime, scaling, and monitoring
  • Database backups and disaster recovery
  • Server signer availability and key share encryption
  • Software upgrades and security patches

Even in SaaS mode, the MPC threshold model ensures The Vault cloud alone cannot move funds. Your mobile signer(s) must participate in every signing session.


Hybrid

The balanced option. Platform services run in The Vault cloud, but one or more MPC key shares remain on your own infrastructure.

You manage:

  • On-premises server signer(s) — hosting, uptime, monitoring
  • Mobile signer devices
  • Your key share backup and recovery procedures

We manage:

  • All cloud-hosted platform services (API gateway, signing coordinator, wallet operations, policy engine, identity, dashboard)
  • Cloud-side server signer
  • Software upgrades for the platform layer

Why hybrid?

The hybrid model lets regulated organisations satisfy key custody requirements without running the full platform stack. By holding a server signer on-premises, you ensure that no signing operation can complete without infrastructure you control — while still benefiting from managed platform services.


On-Premises (Self-Hosted)

The full sovereignty option. Every component — services, signers, database, and key material — runs within your own network perimeter.

You manage:

  • Compute platform provisioning and maintenance
  • All Vault services (deployed from the platform’s deployment package)
  • Database hosting, backups, and disaster recovery
  • KMS configuration and key management
  • Network security, TLS certificates, and access controls
  • Software upgrades (new releases provided by The Vault)

We provide:

  • The deployment package, installation runbook, and operator CLI
  • Technical onboarding and upgrade guidance
  • Security advisories and patch releases

On-premises deployment supports the same API surface and feature set as the cloud deployment. The only difference is infrastructure ownership and operational responsibility.


Key Sovereignty

Across all deployment models, The Vault’s configurable k-of-n MPC threshold (default 3-of-4) ensures that no single party can unilaterally move funds.

DeploymentWho holds key sharesCan The Vault move funds alone?
SaaS2 server shares (The Vault cloud) + 2 mobile shares (your devices)No — requires at least 1 mobile signer
Hybrid1 server share (cloud) + 1 server share (your infra) + 2 mobile shares (your devices)No — requires your signer + mobile
On-Premises2 server shares (your infra) + 2 mobile shares (your devices)N/A — The Vault has no access

In every model, at least one key share that you physically control must participate in every signing ceremony. This is a cryptographic guarantee, not a policy setting — it cannot be bypassed.


Data Residency

With on-premises or hybrid deployment, you control where sensitive data lives:

Data TypeSaaSHybridOn-Premises
Encrypted key sharesThe Vault cloudSplitYour infrastructure
Transaction recordsThe Vault cloudThe Vault cloudYour infrastructure
Audit logsThe Vault cloudThe Vault cloudYour infrastructure
User identity dataThe Vault cloudThe Vault cloudYour infrastructure
KMS root keyThe Vault-managed KMSYour KMSYour KMS

If your organisation is subject to data residency regulations (e.g., GDPR, MAS TRM, local banking rules), consider on-premises or hybrid deployment to ensure all regulated data remains within your jurisdictional boundary.


Choosing a Model

SaaS is the right choice. You get a production-ready custody platform in days, with no infrastructure to manage. You still hold mobile signer devices, so funds cannot move without your explicit participation.


Next Steps

  • On-Premises Installation — deployment overview, prerequisites, and what’s in the onboarding package
  • Key Backup — backup procedures for each deployment model
  • Operations — monitoring, backup, disaster recovery, and upgrades